Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Potential information disclosure relating to CRM-ISA, SAP security note 1900036

SAP Note 1900036

SAP security note 1900036, "Potential information disclosure relating to CRM-ISA", is a note. Below are the symptom, SAP recommended solution and the affected software components.

Description

Symptom

An attacker can discover information relating to E-Commerce/Web Channel that is used to deliver CRM-ISA. This information could be used to allow the attacker to specialize their attacks against E-Commerce/Web Channel and CRM-ISA.

Solution

This note contains Java correction(s) for E-Commerce and Web Channel.

  • Apply the Support Package patch level attached to this note.
  • For more information about applying Java patches, refer to Note 877887.
  • See Note 1546959 for information about the patch strategy.

Reason and prerequisites

Information such as database credentials can be discovered using CRM-ISA. This information may be used by an attacker to further target E-Commerce/Web Channel.

CVSS

Score 4.0 Vector: AV:N/AC:L/AU:S/C:P/I:N/A:N

Affected components

  • SAP-CRMJAV (Versions: 5.0, 6.0, 700, 701, 702, 730, 731, 732, 733)
  • SAP-CRMWEB (Versions: 5.0, 6.0, 700, 701, 702, 730, 731, 732, 733)
  • SAP-SHRWEB (Versions: 5.0, 6.0, 700, 701, 702, 730, 731, 732, 733)
  • SAP-SHRJAV (Versions: 5.0, 6.0, 700, 701, 702, 730, 731, 732, 733)
  • SAP-CRMAPP (Versions: 5.0, 6.0, 700, 701, 702, 730, 731, 732, 733)
  • SAP-SHRAPP (Versions: 5.0, 6.0, 700, 701, 702, 730, 731, 732, 733)

Full note on SAP: SAP Support Launchpad note 1900036

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More